[Speakers]
Adversary Village at
DEF CON 34

Daniel Isler

Awareness & Social Engineering Consultant - Team Leader - SEK

Daniel Isler, holds a Bachelor's degree in Performing Arts, weaponizing his background in theatrical representation, pretexting, and human behavior to reverse-engineer corporate conditioning. Active in the offensive security field since 2015, he serves as the Team Leader of Fr1endly RATs, the specialized social engineering and initial access for Red Team unit at SEK. Certified in OSINT, Red Team, and Social Engineering, he has spent nearly a decade architecting both high-fidelity tactical intrusions and enterprise Awareness service lines. His unique approach relies on a multidisciplinary, highly creative team of elite operators who strictly design and deliver educational content based on the advanced threat techniques they actively execute in the field.

Hey Red Teamer, I've Got a Human EDR Bypass for You...

15:15-15:45 PDT | Friday, Aug 7th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center
Talk

Abstract

Subtitle: The Scout's Field Guide to human risk telemetry: Weaponizing complacent corporate conditioning, tracking the legacy Human EDR, and surviving the wilderness.


Enterprise security leadership is currently suffering from a dangerous cognitive bias: confusing compliance with operational resilience. When an organization achieves a "1.5% phishing click-rate," the board celebrates under the illusion that their perimeter is secure. But to an advanced adversary, that dashboard isn't a shield it's a deterministic roadmap of the target's behavioral heuristics.


Framed as a retro-futuristic, illustrated Scout's Field Guide, this talk exposes how advanced Red Teams and APT actors reverse-engineer corporate human risk telemetry to achieve rapid initial access without advanced code. We will dissect how standardized training inadvertently programs a rigid "Human EDR" based on static signatures, and how operators can fly beneath the radar by simply omitting what the user has been conditioned to look for.


Furthermore, we will unlock a highly unique, unexplored exploitation vector: Behavioral Inheritance (The Legacy Human EDR). Attendees will learn how to conduct passive OSINT on a high-value target's professional history to predict their automated reactions, weaponizing the cognitive conditioning they inherited from their previous employers to bypass structural controls during their onboarding window.


Instead of chasing compliance or deploying new tools, this presentation concludes by turning offensive telemetry into zero-cost tactical defense. We will demonstrate how to evolve from static detection to pure behavioral resilience by implementing "Interrupt Protocols" to break an attacker's live performance, and adopting a "No-Fault Reporting" culture to drastically reduce adversary dwell time. We are unifying Red Team tradecraft with existing human telemetry to survive the corporate wilderness using the adversary's own playbook against them.

Talk outline

00:00 - 05:00 | Introduction: The Mirage of the Safe Camp & The Metric Illusion
Visual & Conceptual Hook: Opening with the retro-futuristic visual theme. I will actively challenge the audience's perception of the "ideal" phishing click-rate to expose the Compliance Paradox: why a "1.5% click-rate" isn't a victory, but a deterministic roadmap of predictable human heuristics.
Defining the "Human EDR": Explaining how continuous, rigid awareness training inadvertently configures the human mind with static detection rules. The employee is conditioned to seek specific visual signatures to fulfill their corporate duty.


05:00 - 12:00 | Stage 1: The Tracking Badge (Perception OSINT & Vendor Footprinting)
Dismantling the Black Box Fallacy: Moving away from blind social engineering toward intelligence-driven human reconnaissance.
Mapping Defensive Firmware: A practical walkthrough of how I passively map a target's human defense ecosystem using OSINT (public portals, historical job descriptions, and LinkedIn certifications).
The Telemetry Exploit: Demonstrating how discovering the specific security awareness vendor used by the target grants instant access to their template library, revealing exactly which vectors are heavily "burned" and which cognitive blind spots remain unconditioned.


12:00 - 22:00 | Stage 2: The Inheritance & Wilderness Badges (Exploiting the Perimeter Blind Spot)
Behavioral Inheritance: Exploring the scenario of newly onboarded hires. I will reverse-engineer a target's professional legacy to map the specific cognitive conditioning implanted by their previous employers.
The Wilderness Exploit: Shifting focus to decentralized, mobile-first personnel. I will break down how attackers trigger inherited habits of automatic obedience during high-stress windows (like onboarding).
Execution Dynamics: Outlining the mechanics of delivering cross-channel prompts to unmanaged devices, completely evading network-level infrastructure controls to gain clean initial access.


22:00 - 30:00 | Stage 3: The Ranger's Pact (Zero-Cost Tactical Mitigations & Q&A)
Breaking the Silos (Human Grey Box Operations): Exposing the operational gap between isolated Red Teams and Security Awareness departments, proposing a unified ecosystem.
Runtime Performance Disruption: Moving away from static detection. I will discuss the implementation of "Interrupt Protocols," training users to actively break the conversational rhythm of a live, multi-channel attack using immutable verification channels.
Minimizing Adversary Dwell Time: Concluding with the adoption of a strict "No-Fault Reporting" framework. Eliminating psychological shame ensures immediate telemetry delivery, killing the attacker's window of opportunity before lateral movement occurs.


Audience Q&A.

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!